216.73.216.6

Booking.com Phishing Campaign Targeting Hotels and Customers

· Published 13/01/2026 19:46 · Modified 14/01/2026 11:12

Export JSON

Essential information

Published
13/01/2026 19:46
Modified
14/01/2026 11:12
Tags
2025-11-07 2026-01-13 booking.com clickfix credential-theft cybercrime hospitality phishing purerat social engineering
Related entities
56 observables, 20 techniques (mitre), 1 malware, 67 others

Description

A sophisticated campaign targeting the industry has been uncovered, compromising hotel administrators' accounts to defraud customers. The attack chain begins with spear- emails impersonating , leading to malware infection via the tactic. The malware, identified as , allows attackers to steal credentials and access booking platforms. Compromised accounts are then used to send fraudulent messages to hotel guests, tricking them into paying for their reservations a second time. The ecosystem supporting these attacks includes services for harvesting hotel administrator contacts, distributing emails, and trading stolen account credentials on underground forums.

External references